EP0729252B1 - Verwaltung kryptographischer Schlüssel - Google Patents
Verwaltung kryptographischer Schlüssel Download PDFInfo
- Publication number
- EP0729252B1 EP0729252B1 EP96300116A EP96300116A EP0729252B1 EP 0729252 B1 EP0729252 B1 EP 0729252B1 EP 96300116 A EP96300116 A EP 96300116A EP 96300116 A EP96300116 A EP 96300116A EP 0729252 B1 EP0729252 B1 EP 0729252B1
- Authority
- EP
- European Patent Office
- Prior art keywords
- cryptographic
- key
- keys
- cryptographic key
- csf
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Lifetime
Links
- 238000000034 method Methods 0.000 claims description 8
- 238000012545 processing Methods 0.000 claims description 6
- 230000004044 response Effects 0.000 description 9
- 238000012795 verification Methods 0.000 description 8
- 238000013478 data encryption standard Methods 0.000 description 6
- 230000008676 import Effects 0.000 description 5
- 239000013598 vector Substances 0.000 description 5
- 210000001175 cerebrospinal fluid Anatomy 0.000 description 4
- 238000004891 communication Methods 0.000 description 3
- 241000207961 Sesamum Species 0.000 description 2
- 235000003434 Sesamum indicum Nutrition 0.000 description 2
- 238000010586 diagram Methods 0.000 description 2
- 230000000873 masking effect Effects 0.000 description 2
- 230000009471 action Effects 0.000 description 1
- 238000013459 approach Methods 0.000 description 1
- 238000009795 derivation Methods 0.000 description 1
- 238000013461 design Methods 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 238000013507 mapping Methods 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 230000008569 process Effects 0.000 description 1
- 230000003313 weakening effect Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/088—Usage controlling of secret information, e.g. techniques for restricting cryptographic keys to pre-authorized uses, different access levels, validity of crypto-period, different key- or password length, or different strong and weak cryptographic algorithms
Definitions
- This invention relates to cryptographic key management in data processing systems. More specifically, the invention is concerned with a mechanism for enforcing cryptographic control policies.
- policies specifying which cryptographic controls are to be applied can be defined in a file issued by the system supplier and tied into a specific customer (e.g. by hashing the file using a one-way function using the licence key and customer identity as initialisation vectors).
- Such controls could include:
- the key tags may be used to control:
- the object of the present invention is to provide an extension of the key tagging concept, in order to support the control of the application of cryptographic control policies.
- this shows a distributed data processing system 10, including a number of applications 11,12. It is assumed that one of these applications 11 (referred to as the client) wishes to set up a secure communication with another application 12, referred to as the server.
- the system also includes a key distribution service (KDS) 13, whose purpose is to distribute cryptographic keys to the applications.
- KDS key distribution service
- Each of the applications 11,12 and the KDS 13 has a respective cryptographic support facility (CSF) 14,15,16 associated with it.
- Each application 11,12 has its own key encrypting key (KEK), which is held securely in its own CSF.
- the KDS has a key database 17 which holds the KEKs of all the applications, encrypted under a master key MK, known only to the KDS's CSF 16.
- FIG. 2 shows one of the CSFs 14,15,16 in more detail.
- the CSF is a trusted secure module, and includes a key store 21 in which it securely holds keys. Each key held in the store is identified by a handle, which allows the key to be referenced by the associated application or KDS without allowing direct access to the key itself.
- Each CSF also includes a key management function 22, a key generation function 23 and a cryptographic operation function 24.
- the key management function 22 is used for checking key tags, and enforcing any restrictions imposed by those tags.
- the key generation function 23 is used for generating and deriving keys.
- the cryptographic operation function 24 is used for encryption, decryption and integrity protection.
- the cryptographic keys may for example be DES keys, as described in FIPS Pub 40, Data Encryption Standard, National Bureau of Standard (now National Institute of Standards and Technology), U.S. Department of Commerce, 1977.
- Bit 7 denotes the most significant bit, and bit 0 denotes the least significant.
- Bit Meaninq if set ( 1) 7 key can be used to protect data 6 key can be used to protect keys 5 key can be used to encipher 4 key can be used to decipher 3 key can be used for integrity seal generation 2 key can be used for integrity seal verification 1 reserved 0 continued in next byte
- a key can be tagged as being able to protect both data and keys. This is in order to support protocols where a single session key may be used to protect requests for keys and also to protect keys returned from the KDS.
- tag byte 1 will be the last (and only) tag byte; otherwise tag byte 2 will follow tag byte 1.
- the keys and their associated tags are encrypted together whenever they are sent outside the trusted CSF. Hence, users or user processes will be unable to modify the settings of the key tags. Whenever the CSF is invoked to use a key, it will take into account the key tags appended to that key, e.g. to determine whether it is permissible to use the key to derive other keys and whether to apply cryptographic control policies before the key is used.
- this shows the operation of the client 11 when it wishes to set up a secure communication with the server 12.
- the server when the server receives this secure association request message, it similarly imports the encrypted basic key BK into its CSF and uses it and the accompanying dialog key packages to derive the same dialog keys as the client. The client and server may then use the dialog keys to send messages to each other in a secure manner.
- the client and server may derive as many dialog keys for use between themselves as required, without further recourse to the KDS.
- this shows the operation of the KDS when it receives a request from a client for a basic key for use with a named server.
- this shows the operation of a CSF when it receives a call requesting it to generate a dialog key.
- the call includes the handle of the basic key BK, and also includes a seed value to be used in key generation.
- the client and server applications may call their respective CSFs to use this key for enciphering, deciphering, integrity seal generation, and integrity seal verification.
- FIG 7 shows the operation of a CSF when called by an application to encipher data.
- the call includes the data to be enciphered, along with the handle of the dialog key to be used.
- the above description has discussed how the CSFs enforce the application of cryptographic control policies to dialog keys which are derived by two peers from basic keys generated by the key distribution service (KDS).
- KDS key distribution service
- the CSFs are also able to enforce the application of cryptographic control policies to keys which are generated directly (i.e. generated by applications rather than by the KDS), as will now be described.
- the default action of a CSF is to apply cryptographic control policies to all keys that are generated or derived unless overridden by the KDS.
- derived keys the tagging of the basic key (generated by the KDS) controls whether the derived dialog keys will be subject to cryptographic control policies.
- keys generated by applications these will be subject to cryptographic control policies.
- direct key generation facilities are not available to applications thus making key derivation the only option.
- a derived key is tagged so that it cannot be used itself in order to derive other keys.
- keys can only be derived from basic key generated by the KDS.
- the KDS will have a special version of the direct key generation interface to the CSF which allows the KDS to direct the settings of the key tags for:
- KDS will allow the KDS to generate keys that are not subject to cryptographic control policies for use by the security infrastructure. It will also allow the KDS to generate untagged keys for use with external systems, such as Kerberos, DCE and SESAME, that do not support tagged keys and thus would misinterpret the key tags as part of the key value.
- external systems such as Kerberos, DCE and SESAME
- the KDS could still request that the CSF apply cryptographic control policies on a generated session key in order to weaken the privacy of user data communicated between a Kerberos or DCE client and server (as these are using the KDS of an export controlled product). This cannot be done for SESAME, as a basic key is generated from which dialog keys are derived external to the export controlled product.
- the KDS would thus need a mapping of target application to security system type in order to know whether the target application would understand tagged keys.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
- Computer And Data Communications (AREA)
Claims (5)
- Kryptographische Unterstützungseinrichtung zur Verwendung in einem Datenverarbeitungssystem, die eine Vorrichtung (21 - 24) zum sicheren Managen von kryptographischen Schlüsseln aufweist, von denen jedem eine Kennung zugeordnet ist,
dadurch gekennzeichnet, dassa) die kryptographische Unterstützungseinrichtung Zugang zu einer Steuerungsmethoden-Datei hat, die eine oder mehrere kryptographische Steuerungen definiert, die kryptographischen Schlüsseln aufgeschaltet werden,b) jede der Kennungen anzeigt, ob der zugeordnete kryptographische Schlüssel einer Steuerungsmethode ausgesetzt sein soll, undc) die kryptographische Unterstützungseinrichtung eine Vorrichtung besitzt, die prüft, ob die einem kryptographischen Schlüssel zugeordnete Kennung anzeigt, dass der kryptographische Schlüssel einer Steuerungsmethode unterliegt, und die, wenn dies der Fall ist, einen Zugriff zu der Steuerungmethoden-Datei vornimmt und die kryptographischen Steuerungen aufschaltet, die durch die Steuerungsmethoden-Datei für den kryptographischen Schlüssel vor der Nutzung dieses kryptographischen Schlüssels oder beliebiger neuer, aus dem kryptographischen Schlüssel generierter kryptographischer Schlüssel festgelegt sind. - Kryptographische Unterstützungseinrichtung nach Anspruch 1, bei dera) jede der Kennungen auch anzeigt, ob der zugeordnete kryptographische Schlüssel berechtigt ist, als Basis zum Generieren neuer kryptographischer Schlüssel verwendet zu werden, undb) die kryptographische Unterstützungseinrichtung ferner eine Vorrichtung aufweist, die auf eine Anfrage zum Generieren eines neuen kryptographischen Schlüssels aus einem bereits vorhandenen kryptographischen Schlüssel anspricht, indem sie die dem vorhandenen kryptographischen Schlüssel zugeordnete Kennung überprüft, und in dem Fall, dass die Kennung anzeigt, dass der vorhandene kryptographische Schlüssel nicht berechtigt ist, als Basis für die Herleitung neuer kryptographischer Schlüssel verwendet zu werden, die Anfrage zurückweist.
- Kryptographische Unterstützungseinrichtung nach Anspruch 1 oder 2, gekennzeichnet durch eine Vorrichtung, die auf eine Anfrage anspricht, um einen der kryptographischen Schlüssel durch Kodieren dieses Schlüssels zusammen mit der zugeordneten Kennung bereit zu stellen, und die den kodierten Schlüssel und die Kennung zurückführt.
- Verfahren zum Betreiben eines Datenverarbeitungssystems, mit einer kryptographischen Unterstützungseinrichtung, die eine Vorrichtung (21 - 24) zum sicheren Managen von kryptographischen Schlüsseln aufweist, deren jeder eine mit ihm verbundene Kennung besitzt, dadurch gekennzeichnet, dassa) die kryptographische Unterstützungseinrichtung Zugriff zu einer Steuerungsmethoden-Datei hat, die festlegt, daß eine oder mehrere kryptographische Steuerungen kryptographischen Schlüsseln aufgeschaltet werden,b) jede der Kennungen anzeigt, ob der zugeordnete kryptographische Schlüssel einer Steuerungsmethode ausgesetzt sein soll, undc) die kryptographische Unterstützungseinrichtung prüft, ob die einem kryptographischen Schlüssel zugeordnete Kennung anzeigt, dass der kryptographische Schlüssel einer Steuerungsmethode ausgesetzt werden soll, und, wenn dies der Fall ist, einen Zugriff zu der Steuerungsmethoden-Datei vornimmt und die kryptographischen Steuerungen, die durch die Steuerungsmethoden-Datei definiert sind, dem kryptographischem Schlüssel aufschaltet bevor der kryptographische Schlüssel oder ein neuer kryptographischer Schlüssel, der aus diesem kryptographischem Schlüssel generiert wird, benutzt wird.
- Verfahren nach Anspruch 4, dadurch gekennzeichnet, dassa) jede der Kennungen ferner anzeigt, ob der zugeordnete kryptographische Schlüssel berechtigt ist, als Basis für das Generieren neuer kryptographischer Schlüssel zu dienen, undb) die kryptographische Unterstützungseinrichtung auf eine Anfrage zum Generieren eines neuen kryptographischen Schlüssels aus einem vorhandenen kryptographischen Schlüssel antwortet, indem die Kennung, die einem vorhandenen kryptographischen Schlüssel zugeordnet ist, geprüft wird, und in dem Fall, dass die Kennung anzeigt, dass der vorhandene kryptographische Schlüssel nicht zur Verwendung als Basis für die Herleitung neuer kryptographischer Schlüssel berechtigt ist, die Anfrage zurückweist.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| GB9503738 | 1995-02-24 | ||
| GBGB9503738.8A GB9503738D0 (en) | 1995-02-24 | 1995-02-24 | Cryptographic key management |
Publications (3)
| Publication Number | Publication Date |
|---|---|
| EP0729252A2 EP0729252A2 (de) | 1996-08-28 |
| EP0729252A3 EP0729252A3 (de) | 1998-05-13 |
| EP0729252B1 true EP0729252B1 (de) | 2003-09-03 |
Family
ID=10770192
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP96300116A Expired - Lifetime EP0729252B1 (de) | 1995-02-24 | 1996-01-05 | Verwaltung kryptographischer Schlüssel |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US5745572A (de) |
| EP (1) | EP0729252B1 (de) |
| DE (1) | DE69629738T2 (de) |
| GB (1) | GB9503738D0 (de) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2008083363A1 (en) * | 2006-12-28 | 2008-07-10 | Intel Corporation | Protecting independent vendor encryption keys with a common primary encryption key |
Families Citing this family (34)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPH07271865A (ja) * | 1994-04-01 | 1995-10-20 | Mitsubishi Corp | データベース著作権管理方法 |
| US6744894B1 (en) | 1994-04-01 | 2004-06-01 | Mitsubishi Corporation | Data management system |
| US7036019B1 (en) * | 1994-04-01 | 2006-04-25 | Intarsia Software Llc | Method for controlling database copyrights |
| US7302415B1 (en) | 1994-09-30 | 2007-11-27 | Intarsia Llc | Data copyright management system |
| DE69532434T2 (de) | 1994-10-27 | 2004-11-11 | Mitsubishi Corp. | Gerät für Dateiurheberrechte-Verwaltungssystem |
| US6424715B1 (en) | 1994-10-27 | 2002-07-23 | Mitsubishi Corporation | Digital content management system and apparatus |
| DE69535013T2 (de) | 1994-10-27 | 2006-12-28 | Intarsia Software LLC, Las Vegas | Urheberrechtsdatenverwaltungssystem |
| US8595502B2 (en) * | 1995-09-29 | 2013-11-26 | Intarsia Software Llc | Data management system |
| US7801817B2 (en) * | 1995-10-27 | 2010-09-21 | Makoto Saito | Digital content management system and apparatus |
| GB9719726D0 (en) * | 1997-09-16 | 1998-03-18 | Simoco Int Ltd | Encryption method and apparatus |
| JP4763866B2 (ja) | 1998-10-15 | 2011-08-31 | インターシア ソフトウェア エルエルシー | 2重再暗号化によりデジタルデータを保護する方法及び装置 |
| JP2002529012A (ja) | 1998-10-23 | 2002-09-03 | エル3 コミュニケーションズ コーポレイション | 異質の暗号資産におけるキイの資料を管理する装置および方法 |
| US6611913B1 (en) * | 1999-03-29 | 2003-08-26 | Verizon Laboratories Inc. | Escrowed key distribution for over-the-air service provisioning in wireless communication networks |
| US6658567B1 (en) | 1999-06-25 | 2003-12-02 | Geomechanics International, Inc. | Method and logic for locking geological data and an analyzer program that analyzes the geological data |
| US20020018571A1 (en) * | 1999-08-31 | 2002-02-14 | Anderson Walter F. | Key management methods and communication protocol for secure communication systems |
| US7051067B1 (en) * | 1999-11-22 | 2006-05-23 | Sun Microsystems, Inc. | Object oriented mechanism for dynamically constructing customized implementations to enforce restrictions |
| US7131008B1 (en) | 1999-11-22 | 2006-10-31 | Sun Microsystems, Inc. | Mechanism for dynamically constructing customized implementations to enforce restrictions |
| US7103910B1 (en) * | 1999-11-22 | 2006-09-05 | Sun Microsystems, Inc. | Method and apparatus for verifying the legitimacy of an untrusted mechanism |
| US6721888B1 (en) | 1999-11-22 | 2004-04-13 | Sun Microsystems, Inc. | Mechanism for merging multiple policies |
| US6792537B1 (en) | 1999-11-22 | 2004-09-14 | Sun Microsystems, Inc. | Mechanism for determining restrictions to impose on an implementation of a service |
| JP2002271312A (ja) * | 2001-03-14 | 2002-09-20 | Hitachi Ltd | 公開鍵管理方法 |
| RU2207736C2 (ru) * | 2001-04-20 | 2003-06-27 | Государственное предприятие конструкторское бюро "СПЕЦВУЗАВТОМАТИКА" | Способ шифрования блоков данных |
| US7660421B2 (en) * | 2002-06-28 | 2010-02-09 | Hewlett-Packard Development Company, L.P. | Method and system for secure storage, transmission and control of cryptographic keys |
| US7590845B2 (en) * | 2003-12-22 | 2009-09-15 | Lenovo Singapore Pte. Ltd. | Key cache management through multiple localities |
| RU2262204C1 (ru) * | 2004-07-23 | 2005-10-10 | ЗАО "НИЦ "Сфера" | Способ шифрования двоичной информации и устройство для осуществления способа |
| US7873166B2 (en) | 2005-09-13 | 2011-01-18 | Avaya Inc. | Method for undetectably impeding key strength of encryption usage for products exported outside the U.S |
| US7987349B2 (en) * | 2007-06-29 | 2011-07-26 | Intel Corporation | Encryption acceleration |
| KR100954223B1 (ko) * | 2007-11-22 | 2010-04-21 | 한국전자통신연구원 | Rtc를 이용하는 암호시스템간 보안 통신 방법 및 장치 |
| GB2455796A (en) * | 2007-12-21 | 2009-06-24 | Symbian Software Ltd | Mechanism for controlling access to a key store |
| KR101240552B1 (ko) * | 2011-09-26 | 2013-03-11 | 삼성에스디에스 주식회사 | 미디어 키 관리 및 상기 미디어 키를 이용한 피어-투-피어 메시지 송수신 시스템 및 방법 |
| CN105991563B (zh) | 2015-02-05 | 2020-07-03 | 阿里巴巴集团控股有限公司 | 一种保护敏感数据安全的方法、装置及三方服务系统 |
| US10880281B2 (en) * | 2016-02-26 | 2020-12-29 | Fornetix Llc | Structure of policies for evaluating key attributes of encryption keys |
| EP3599737A1 (de) * | 2018-07-24 | 2020-01-29 | Gemalto Sa | Verfahren zum erstellen eines primären kryptographischen schlüssels mit benutzerdefinierten transformationsregeln |
| RU2756976C1 (ru) * | 2020-06-08 | 2021-10-07 | федеральное государственное автономное образовательное учреждение высшего образования "Северо-Кавказский федеральный университет" | Способ шифрования информации и устройство для осуществления способа |
Family Cites Families (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US4850017A (en) * | 1987-05-29 | 1989-07-18 | International Business Machines Corp. | Controlled use of cryptographic keys via generating station established control values |
| US4941176A (en) * | 1988-08-11 | 1990-07-10 | International Business Machines Corporation | Secure management of keys using control vectors |
| DE68926200T2 (de) * | 1988-08-11 | 1996-10-17 | Ibm | Geheime Datenübertragung mittels Steuervektoren |
| US4924515A (en) * | 1988-08-29 | 1990-05-08 | International Business Machines Coprporation | Secure management of keys using extended control vectors |
| US4918728A (en) * | 1989-08-30 | 1990-04-17 | International Business Machines Corporation | Data cryptography operations using control vectors |
| US4993069A (en) * | 1989-11-29 | 1991-02-12 | International Business Machines Corporation | Secure key management using control vector translation |
| US5007089A (en) * | 1990-04-09 | 1991-04-09 | International Business Machines Corporation | Secure key management using programable control vector checking |
| JP2689998B2 (ja) * | 1990-08-22 | 1997-12-10 | インターナショナル・ビジネス・マシーンズ・コーポレイション | 暗号動作を行う装置 |
| US5142578A (en) * | 1991-08-22 | 1992-08-25 | International Business Machines Corporation | Hybrid public key algorithm/data encryption algorithm key distribution method based on control vectors |
| US5164988A (en) * | 1991-10-31 | 1992-11-17 | International Business Machines Corporation | Method to establish and enforce a network cryptographic security policy in a public key cryptosystem |
-
1995
- 1995-02-24 GB GBGB9503738.8A patent/GB9503738D0/en active Pending
-
1996
- 1996-01-05 EP EP96300116A patent/EP0729252B1/de not_active Expired - Lifetime
- 1996-01-05 DE DE69629738T patent/DE69629738T2/de not_active Expired - Lifetime
- 1996-01-17 US US08/588,072 patent/US5745572A/en not_active Expired - Lifetime
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2008083363A1 (en) * | 2006-12-28 | 2008-07-10 | Intel Corporation | Protecting independent vendor encryption keys with a common primary encryption key |
Also Published As
| Publication number | Publication date |
|---|---|
| US5745572A (en) | 1998-04-28 |
| EP0729252A3 (de) | 1998-05-13 |
| DE69629738T2 (de) | 2004-07-08 |
| EP0729252A2 (de) | 1996-08-28 |
| GB9503738D0 (en) | 1995-04-19 |
| DE69629738D1 (de) | 2003-10-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP0729252B1 (de) | Verwaltung kryptographischer Schlüssel | |
| US5555309A (en) | Cryptographic key management apparatus and methods | |
| Blaze | Key Management in an Encrypting File System. | |
| US5214700A (en) | Method for obtaining a securitized cleartext attestation in a distributed data processing system environment | |
| US7200230B2 (en) | System and method for controlling and enforcing access rights to encrypted media | |
| US6185308B1 (en) | Key recovery system | |
| US9866375B2 (en) | Multi-level key management | |
| JP2552061B2 (ja) | 公開キー暗号システムにおいてネットワーク安全保証ポリシーが狂わないようにする方法及び装置 | |
| CA2068488C (en) | Hybrid public key algorithm/data encryption algorithm key distribution method based on control vectors | |
| US6483920B2 (en) | Key recovery process used for strong encryption of messages | |
| CA2100234C (en) | Commercial data masking | |
| US20030079120A1 (en) | Web environment access control | |
| EP1662355A2 (de) | Verfahren und Vorrichtung zur Datenspeicherung auf der Anwendungsschicht bei mobilen Geräten | |
| EP3780483A1 (de) | Verfahren für kryptografische operation, verfahren zur erzeugung eines arbeitsschlüssels und plattform und vorrichtung für kryptografischen dienst | |
| JPH0820848B2 (ja) | 検証方法及び装置 | |
| CN110996319B (zh) | 一种对软件服务做激活授权管理的系统及方法 | |
| CN114267100A (zh) | 开锁认证方法、装置、安全芯片及电子钥匙管理系统 | |
| EP0518466B1 (de) | Datenverarbeitungssystem mit kryptographischem Dienst | |
| US8161565B1 (en) | Key release systems, components and methods | |
| KR19980050938A (ko) | 인터넷 상에서 암호환된 문서 전송방법 | |
| US6493823B1 (en) | Instrument for making secure data exchanges | |
| KR102896664B1 (ko) | 부분 복호화가 가능한 배포 암호문 관리 방법 및 이를 이용하는 관리 시스템 | |
| EP2293211A1 (de) | System zur Verwaltung von digitalen Rechten mit Schutzverfahren für verschiedenartige Inhalte | |
| Nagrale et al. | Data Security of Dynamic and Robust Role Based Access Control from Multiple Authorities in Cloud Environment | |
| CN108768627A (zh) | 印章防伪安全芯片密钥管理控制系统 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): DE FR GB IT NL |
|
| PUAL | Search report despatched |
Free format text: ORIGINAL CODE: 0009013 |
|
| AK | Designated contracting states |
Kind code of ref document: A3 Designated state(s): DE FR GB IT NL |
|
| 17P | Request for examination filed |
Effective date: 19980928 |
|
| 17Q | First examination report despatched |
Effective date: 20011207 |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: FUJITSU SERVICES LIMITED |
|
| GRAH | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOS IGRA |
|
| GRAH | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOS IGRA |
|
| GRAA | (expected) grant |
Free format text: ORIGINAL CODE: 0009210 |
|
| AK | Designated contracting states |
Kind code of ref document: B1 Designated state(s): DE FR GB IT NL |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: NL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20030903 Ref country code: IT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT;WARNING: LAPSES OF ITALIAN PATENTS WITH EFFECTIVE DATE BEFORE 2007 MAY HAVE OCCURRED AT ANY TIME BEFORE 2007. THE CORRECT EFFECTIVE DATE MAY BE DIFFERENT FROM THE ONE RECORDED. Effective date: 20030903 |
|
| REG | Reference to a national code |
Ref country code: GB Ref legal event code: FG4D |
|
| REF | Corresponds to: |
Ref document number: 69629738 Country of ref document: DE Date of ref document: 20031009 Kind code of ref document: P |
|
| NLV1 | Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents act | ||
| ET | Fr: translation filed | ||
| PLBE | No opposition filed within time limit |
Free format text: ORIGINAL CODE: 0009261 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT |
|
| 26N | No opposition filed |
Effective date: 20040604 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: DE Payment date: 20130122 Year of fee payment: 18 Ref country code: GB Payment date: 20130122 Year of fee payment: 18 Ref country code: FR Payment date: 20130213 Year of fee payment: 18 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R119 Ref document number: 69629738 Country of ref document: DE |
|
| GBPC | Gb: european patent ceased through non-payment of renewal fee |
Effective date: 20140105 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R119 Ref document number: 69629738 Country of ref document: DE Effective date: 20140801 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: DE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20140801 |
|
| REG | Reference to a national code |
Ref country code: FR Ref legal event code: ST Effective date: 20140930 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: GB Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20140105 Ref country code: FR Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20140131 |